sl1m_dogg, 2016-03-19 14:55:06

What is wrong with my registration/authentication/authorization (Symfony 2.7)?

Everything was fine with registration, but after I decided to automatically give the user a role during registration, something went wrong. Own code:


namespace MailerBundle\Controller;

use MailerBundle\Entity\User;
use MailerBundle\Form\UserType;
use Symfony\Bundle\FrameworkBundle\Controller\Controller;
use Symfony\Component\HttpFoundation\Request;

class SiteController extends Controller
     * @return \Symfony\Component\HttpFoundation\Response
    public function indexAction()
        return $this->render('MailerBundle:Site:index.html.twig');

    public function loginAction(Request $request)
        $authenticationUtils = $this->get('security.authentication_utils');

        $error = $authenticationUtils->getLastAuthenticationError();

        $lastUsername = $authenticationUtils->getLastUsername();

        return $this->render(
            'MailerBundle:Site:login.html.twig', [
                'last_username' => $lastUsername,
                'error'         => $error,


     * @param Request $request
     * @return \Symfony\Component\HttpFoundation\Response
    public function signupAction(Request $request)
        $user = new User();
        $form = $this->createForm(new UserType(), $user);

        if ($form->isSubmitted() && $form->isValid()) {

            $password = $this->get('security.password_encoder')
                ->encodePassword($user, $user->getPassword());

            $em = $this->getDoctrine()->getManager();

            return $this->redirectToRoute('email');

        return $this->render(
            'MailerBundle:Site:signup.html.twig', [
                'form' => $form->createView()


namespace MailerBundle\Entity;

use Doctrine\Common\Collections\ArrayCollection;
use Doctrine\ORM\Mapping as ORM;
use Symfony\Component\Security\Core\User\UserInterface;

 * @ORM\Table(name="user")
 * @ORM\Entity
class User implements UserInterface, \Serializable
     * @var integer
     * @ORM\Column(name="id", type="integer")
     * @ORM\Id
     * @ORM\GeneratedValue(strategy="AUTO")
    private $id;

     * @var string
     * @ORM\Column(name="name", type="string", length=255, unique=true)
    private $name;

     * @var string
     * @ORM\Column(name="password", type="string", length=255)
    private $password;

     * @param string $password
    public function setPassword($password)
        $this->password = $password;

     * @var array
    private $credentials;

     * @return array
    public function getCredentials()
        return $this->credentials;

     * @param array $credentials
    public function setCredentials($credentials)
        $this->credentials = $credentials;

     * User constructor.
    public function __construct()
        $this->id = uniqid('user', true);
        $this->credentials = ['ROLE_USER'];

     * @return string
    public function getName()
        return $this->name;

     * @return int|string
    public function getId()
        return $this->id;

     * @param $name
    public function setName($name)
        $this->name = $name;

     * @return string
    public function toJson()
        $result = json_encode([
        if (json_last_error()) {
            trigger_error("Cannot encode json");

        return $result;

     * Returns the roles granted to the user.
     * <code>
     * public function getRoles()
     * {
     *     return array('ROLE_USER');
     * }
     * </code>
     * Alternatively, the roles might be stored on a ``roles`` property,
     * and populated in any number of different ways when the user object
     * is created.
     * @return (Role|string)[] The user roles
    public function getRoles()
        return ['ROLE_USER'];

     * Returns the password used to authenticate the user.
     * This should be the encoded password. On authentication, a plain-text
     * password will be salted, encoded, and then compared to this value.
     * @return string The password
    public function getPassword()
        return null;

     * Returns the salt that was originally used to encode the password.
     * This can return null if the password was not encoded using a salt.
     * @return string|null The salt
    public function getSalt()
        return null;

     * Returns the username used to authenticate the user.
     * @return string The username
    public function getUsername()
        return $this->name;

     * Removes sensitive data from the user.
     * This is important if, at any given point, sensitive information like
     * the plain-text password is stored on this object.
    public function eraseCredentials()

     * String representation of object
     * @link http://php.net/manual/en/serializable.serialize.php
     * @return string the string representation of the object or null
     * @since 5.1.0
    public function serialize()
        return serialize([
//            implode(', ', $this->roles)

     * Constructs the object
     * @link http://php.net/manual/en/serializable.unserialize.php
     * @param string $serialized <p>
     * The string representation of the object.
     * </p>
     * @return void
     * @since 5.1.0
    public function unserialize($serialized)
        $unserialized = unserialize($serialized);
            ) =$unserialized;
//        $this->roles = explode(', ', $unserialized['roles']);


namespace MailerrBundle\Entity;

use Symfony\Component\Security\Core\Exception\UnsupportedUserException;
use Symfony\Component\Security\Core\User\UserInterface;
use Doctrine\ORM\EntityRepository;
use Symfony\Component\Security\Core\User\UserProviderInterface;

class UserRepository extends EntityRepository implements UserProviderInterface
    public function loadUserByUsername($username)
        return $this->createQueryBuilder('u')
            ->where('u.name = :name')
            ->setParameter('name', $username)

    public function refreshUser(UserInterface $user)
        $class = get_class($user);
        if (!$this->supportsClass($class)) {
            throw new UnsupportedUserException(
                    'Instances of "%s" are not supported.',

        return $this->find($user->getId());

    public function supportsClass($class)
        return $this->getEntityName() === $class
                   || is_subclass_of($class, $this->getEntityName());

            algorithm: bcrypt

                class: MailerBundle:User
                property: name

            anonymous: ~
                login_path: login
                check_path: login
                target_path_parameter: email
            provider: db_provider

        - { path: ^/email, roles: ROLE_USER }

Who are interested in views and forms, you can see here:

1 answer(s)
Denis, 2016-10-13

Add the role_hierarchy section to security.yml

